IT@JH Enterprise Messaging and Directory is seeking an IAM Engineerwho will be responsible for designing, developing, testing, implementing, and integrating identity and access management frameworks, systems, and protocols. This role involves developing and implementing IAM systems, including Single Sign-On (SSO), authentication, Privilege Identity Management, Privilege Access Management, Certificate Services, PKI, Conditional Access, Data Loss Prevention, and access controls, to ensure the confidentiality, integrity, and availability of IAM systems and data. The IAM Engineer works closely with security teams and other stakeholders to create secure and scalable IAM solutions that meet the organization's needs. IAM Engineers ensure that IAM systems are effectively integrated with existing infrastructure, providing seamless and secure access for users. They conduct regular assessments to identify and mitigate risks, ensuring compliance with security policies and regulatory requirements. IAM Engineers are responsible for ensuring the application of Zero Trust principles for identity and access solutions. The IAM Engineer also stays abreast of emerging IAM technologies and trends, recommending and implementing improvements to enhance the organization's security posture. Specific Duties & Responsibilities
- Develop and Implement IAM Solutions: Design, develop, implement, and maintain identity and access management solutions and systems, including Single Sign-On (SSO), authentication, Privilege Identity Management, Privilege Access Management, Certificate Services, PKI, Conditional Access, Data Loss Prevention, and access controls.
- Technical Troubleshooting: Troubleshoot, identify, and resolve technical IAM-related issues.
- System Improvement: Enhance IAM solutions and systems to protect against evolving threats and improve efficiency.
- Best Practices Coaching: Coach organization members on IAM best practices.
- Stay Informed: Stay up-to-date on current IAM threats and industry solutions.
- Technology Stack Support: Support the IAM technology stack, including monitoring, hygiene, enhancements development, and ensuring operational security systems.
- Active Directory Integration: Assist project teams with Active Directory integration patterns using AD and Azure AD, Azure MFA, ADFS & Azure Federation, and SSO patterns.
- Proactive Problem Solving: Identify gaps and develop solutions to routine problems proactively.
- System Updates: Plan and implement updates to maintain, monitor, and support enterprise IAM tools.
- In-Depth Understanding: Obtain an in-depth understanding of IAM enterprise technologies and key business and security drivers.
- Technology Evaluations: Participate in ongoing technology evaluations and stay current with technology trends and industry standards.
- Customer Communication: Communicate with customers to clarify requests, report status, or provide information as needed.
- Continual Improvement: Drive continual improvement processes to enhance the end-user experience, increase technology value, and improve security posture.
- Stakeholder Collaboration: Work closely with key stakeholders to understand requirements and drive the design, development, and implementation of IAM system improvements.
- Artifact Collection and Testing: Collect and qualify required artifacts, develop test plans, and lead application implementation efforts to ensure success.
- Risk Mitigation: Conduct regular assessments to identify and mitigate risks, ensuring compliance with security policies and regulatory requirements.
- Seamless Integration: Ensure IAM systems are effectively integrated with existing infrastructure, providing seamless and secure access for users.
- Security Posture Enhancement: Recommend and implement improvements to enhance the organization's security posture, staying abreast of emerging IAM technologies and trends.
- Zero Trust Principles: Apply Zero Trust principles to identity and access solutions, ensuring robust security frameworks are in place.
Technical Qualifications and Specialized Certifications
- Extensive IAM Experience: Deep understanding of Identity and Access Management (IAM) principles and technologies.
- IAM Tools: Skilled in designing, implementing, and managing IAM tools and platforms, such as Microsoft Entra, Privileged Access Management (PAM), and Privileged Identity Management (PIM).
- Microsoft 365 Administration: Strong knowledge of Microsoft 365 and related IAM solutions.
- Digital Certificates and PKI: Expertise in managing digital certificates and designing, implementing, and managing Public Key Infrastructures (PKI).
- SSO and MFA Solutions: Familiarity with designing, implementing, and maintaining Single Sign-On (SSO) and Multi-Factor Authentication (MFA) solutions.
- Zero Trust Principles: In-depth understanding of Zero Trust principles and their application in IAM.
- Programming/Scripting Skills: Proficiency in programming or scripting languages such as PowerShell, Python, and SQL.
- Technical Troubleshooting: Strong skills in troubleshooting and resolving IAM-related technical issues.
- System Improvement: Experience in enhancing IAM solutions to counter evolving threats and improve efficiency.
- Active Directory Integration: Knowledge of Active Directory and Azure AD integration patterns, including Azure MFA, ADFS, and SSO patterns.
- Risk Assessment and Mitigation: Ability to conduct regular assessments to identify and mitigate risks, ensuring compliance with security policies and regulatory requirements.
- Technology Stack Support: Experience in supporting the IAM technology stack, including monitoring, hygiene, and enhancements development.
- Stakeholder Collaboration: Proven ability to work closely with key stakeholders to understand requirements and drive the design, development, and implementation of IAM system improvements.
- Continual Improvement: Commitment to driving continual improvement processes to enhance the end-user experience, increase technology value, and improve security posture.
- Customer Communication: Strong communication skills to clarify requests, report status, and provide information as needed.
- Technology Evaluations: Participation in ongoing technology evaluations and staying current with technology trends and industry standards.
Special Knowledge, Skills, and Abilities
- Must possess strong technical skills and independently stay current with identity and access management technology and best practices.
- Ability to establish priorities, work independently, and proceed with objectives without supervision.
- Must demonstrate strong critical thinking and analytical reasoning skills.
- Ability to work on multiple priorities effectively.
- Ability to execute assigned project tasks within an established schedule.
- Ability to work collaboratively in a hybrid team environment.
- Ability to communicate effectively in the service of users and colleagues.
- Writes and communicates clearly and concisely.
- Possesses sound documentation skills.
- Ability to maintain confidentiality.
- Must demonstrate exemplary customer service skills.
Specific Devices, Software, Projects
- Responsible for the entire identity lifecycle for all JH Identities
- Microsoft SQL
- Powershell
- Microsoft Identity Manager
- Azure AD Connect
- School Data Sync
- Azure Active Directory
- SQL Reporting Services
- PowerBI
Scale/Size of Area, Project and/or System Supported
- IAM Team oversees the management of hundreds of thousands of accounts across multiple Azure tenants, ensuring secure and streamlined identity solutions on an enterprise scale.
- Responsible for numerous data integrations that support essential enterprise operations.
- Includes large-scale projects that drive the success of enterprise initiatives, leveraging identity and access management to support secure, efficient, and compliant data usage throughout the organization.
On Call Requirements
- Yes, this position requires participation in the on-call rotation, with each rotation lasting one week.
Minimum Qualifications
- Bachelor's Degree required.
- Five years of related experience in identity and access management (IAM), cybersecurity, computer science, computer information systems, or related fields.
- Additional education may substitute for required experience, and additional experience may substitute for required education to the extent permitted by the JHU equivalency formula.
Preferred Qualifications
- Bachelor's degree in computer science, information technology, or a related field.
Classified Title: IAM Engineer Role/Level/Range: ATP/04/PF Starting Salary Range: $85,500 - $149,800 Annually (Commensurate w/exp.) Employee group: Full Time Schedule: Mon-Fri 8:30am-5:00pm FLSA Status:Exempt Location:Remote Department name: IT@JH Enterprise Directory and Messaging Personnel area: University Administration
Total Rewards The referenced base salary range represents the low and high end of Johns Hopkins University's salary range for this position. Not all candidates will be eligible for the upper end of the salary range. Exact salary will ultimately depend on multiple factors, which may include the successful candidate's geographic location, skills, work experience, market conditions, education/training and other qualifications. Johns Hopkins offers a total rewards package that supports our employees' health, life, career and retirement. More information can be found here: https://hr.jhu.edu/benefits-worklife/. Education and Experience Equivalency Please refer to the job description above to see which forms of equivalency are permitted for this position. If permitted, equivalencies will follow these guidelines: JHU Equivalency Formula: 30 undergraduate degree credits (semester hours) or 18 graduate degree credits may substitute for one year of experience. Additional related experience may substitute for required education on the same basis. For jobs where equivalency is permitted, up to two years of non-related college course work may be applied towards the total minimum education/experience required for the respective job. Applicants Completing Studies Applicants who do not meet the posted requirements but are completing their final academic semester/quarter will be considered eligible for employment and may be asked to provide additional information confirming their academic completion date. Background Checks The successful candidate(s) for this position will be subject to a pre-employment background check. Johns Hopkins is committed to hiring individuals with a justice-involved background, consistent with applicable policies and current practice. A prior criminal history does not automatically preclude candidates from employment at Johns Hopkins University. In accordance with applicable law, the university will review, on an individual basis, the date of a candidate's conviction, the nature of the conviction and how the conviction relates to an essential job-related qualification or function. Diversity and Inclusion The Johns Hopkins University values diversity, equity and inclusion and advances these through our key strategic framework, the JHU Roadmap on Diversity and Inclusion. Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. EEOis the Law https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12ScreenRdr.pdf Accommodation Information If you are interested in applying for employment with The Johns Hopkins University and require special assistance or accommodation during any part of the pre-employment process, please contact the Talent Acquisition Office at jhurecruitment@jhu.edu. For TTY users, call via Maryland Relay or dial 711. For more information about workplace accommodations or accessibility at Johns Hopkins University, please visit https://accessibility.jhu.edu/. Vaccine Requirements Johns Hopkins University strongly encourages, but no longer requires, at least one dose of the COVID-19 vaccine.The COVID-19 vaccine does not apply to positions located in the State of Florida. We still require all faculty, staff, and students to receive the seasonal flu vaccine. Exceptions to the COVID and flu vaccine requirements may be provided to individuals for religious beliefs or medical reasons. Requests for an exception must be submitted to the JHU vaccination registry.This change does not apply to the School of Medicine (SOM). SOM hires must be fully vaccinated with an FDA COVID-19 vaccination and provide proof of vaccination status. For additional information, applicants for SOM positions should visit https://www.hopkinsmedicine.org/coronavirus/covid-19-vaccine/and all other JHU applicants should visit https://covidinfo.jhu.edu/health-safety/covid-vaccination-information/. The following additional provisions may apply, depending upon campus. Your recruiter will advise accordingly. The pre-employment physical for positions in clinical areas, laboratories, working with research subjects, or involving community contact requires documentation of immune status against Rubella (German measles), Rubeola (Measles), Mumps, Varicella (chickenpox), Hepatitis B and documentation of having received the Tdap (Tetanus, diphtheria, pertussis) vaccination. This may include documentation of having two (2) MMR vaccines; two (2) Varicella vaccines; or antibody status to these diseases from laboratory testing. Blood tests for immunities to these diseases are ordinarily included in the pre-employment physical exam except for those employees who provide results of blood tests or immunization documentation from their own health care providers. Any vaccinations required for these diseases will be given at no cost in our Occupational Health office.
|